CVE-2026-101283
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
| CWE | CWE-122 |
| Vendor | esnet |
| Product | iperf3 |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for esnet iperf3
Be the first to know when new unknown vulnerabilities affecting esnet iperf3 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
esnet / iperf3
3.20 3.21
References
Credits
Anthropic Ada Logics